.
Bitland.Net Security Notes            Comments? email jwilkins-at-bitland*net
More information on the author at Jonathan Wilkins's home page
RSS feed available at http://www.bitland.net/index.rss               Add to Google
Archives: 2007, 2006, 2005, 2004, 2003, 2002, 2001, 2000


XSS Cheat Sheet  |  (2005/05/25 14:15)

RSnake has a really handy XSS Cheat Sheet. It won't help you if you don't understand XSS attacks to begin with, but it's a pretty complete list of variants and obfuscation techniques.

+digg  |  +del.icio.us   |    [Security ]   |   Permanent link

CallerID spoofing  |  (2005/05/25 11:45)

This is old news, but I've run into a few people lately who still weren't aware, so I dug up some fresh links. The basic gist is that spoofing caller id is easy and so any authentication system that relies on valid CID info is broken.
RootSecure.net covers CallerID spoofing w/ Linux and Asterix.
There are also a few services that make things trivial.
SpoofTel
CamoPhone

+digg  |  +del.icio.us   |    [Phones ]   |   Permanent link

RSS feed available at http://www.bitland.net/index.rss